Hacker Newsnew | past | comments | ask | show | jobs | submit | snorbleck's commentslogin

So basically, Edge, Brave and any other browser built on Chromium. Nice.

Monocultures are great!

There’s a reason I use Firefox (Gecko). Also, Ladybird—another completely different web engine—is really promising. I spent five hours building it from source, having it take about 8 gigabytes of space, and it perfectly renders my own webpages and blogs.

I have a feeling someone’s going to make an open source browser using Ladybird’s engine before Ladybird has official binaries.


Is Firefox actually safer than Chromium-based browsers though?

I know this is old: https://madaidans-insecurities.github.io/firefox-chromium.ht...

but has the situation changed substantially in favor of Firefox?


It looks like more of Firefox has been ported over to Rust since then:

https://www.wilderssecurity.com/threads/security-chromium-ve...

The reason why I support Gecko and Ladybird’s engine is because I am opposed to monoculture, however. Even if Gecko (Firefox) is less secure than Chromium (Chrome, Edge, etc.), by not having a monoculture, a Chrome exploit will only take down the subset of people using the Chromium ecosystem, and not affect Gecko users. Alas, most people are in the Chromium ecosystem right now so that means malicious hackers only need to target one codebase.

It’s the same reason I wrote MaraDNS back in 2001—back then, there was only one open source DNS server[1,2] so I wrote another one.[3]

[1] Djbdns was around back then but wasn’t open source, which limited its adoption.

[2] https://lwn.net/2001/0208/

[2] MaraDNS was and is optimized for running at most a few dozen domains on a system running a bunch of other services, where one does not want the DNS server causing security problems for the server, and where the DNS server needs to be lightweight as possible.


No. The post applies to Android, but the situation is significantly worse on desktop platforms since Android at least has OS-level sandboxing, etc.

https://www.reddit.com/r/GrapheneOS/comments/1unhtxu/initial...


Running Firefox on all my OSes. Nice.

are they really "destroyed" if the original is preserved on some other medium though?


now bring back the original packetstorm :)


not only writing, but drawing, art, putting a pen or pencil to paper/tablet and just flowing is great to keep the brain muscle active.


you can, but it's better to use a different model or higher effort level at the very least to do the verifying part. (haven't checked to see what it is they are doing exactly), but doing vulnerability validation with the same model and effort you used to find the vulnerabilities isn't going to be a true second set of eyes and the model will likely always just try and justify it was right in the first place. ime, it's better to start with a fresh, clean context and at the very least a higher effort level on the same model. pass the finding(s) to a model that hasn't seen it before and it will judge it with an unbiased perspective.


WHAT IF, the author is the LLM?


thoughts?


you can access the site at C:\mywebsites\course\index.html


making mountains out of mole hills. this type of panic is really common in the infosec world.


How so? I tend to disagree with the general statement that this is common in the infosec world, but I'd like to understand better what you mean by that.


Impact in this case, is non-existent (Wow they got my email)

> I'd like to understand better what you mean by that.

Recall there was a period where every CPU sidechannel attack had a dedicated (wow) website and a rock band name assigned to it (when in reality their impact again, was/is limited).


so good!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: